CCNA 2 (Version 7.00) SRWE Practice Final Exam

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/177

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 8:29 PM on 3/28/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

178 Terms

1
New cards

An employee connects wirelessly to the company network using a cell phone. The employee then configures the cell phone to act as a wireless access point that will allow new employees to connect to the company network. Which type of security threat best describes this situation?

cracking

denial of service

rogue access point

spoofing

rogue access point

2
New cards

1. A network administrator is using the router-on-a-stick method to configure inter-VLAN routing. Switch port Gi1/1 is used to connect to the router. Which command should be entered to prepare this port for the task?

Switch(config)# interface gigabitethernet 1/1Switch

(config-if)# spanning-tree vlan 1

Switch(config)# interface gigabitethernet 1/1Switch

(config-if)# spanning-tree portfast

Switch(config)# interface gigabitethernet 1/1Switch

(config-if)# switchport mode trunk

Switch(config)# interface gigabitethernet 1/1Switch

(config-if)# switchport access vlan 1

Switch(config)# interface gigabitethernet 1/1Switch

(config-if)# switchport mode trunk

3
New cards

Which combination of WLAN authentication and encryption is recommended as a best practice for home users?

WPA2 and AES

WEP and RC4

WPA and PSK

EAP and AES

WEP and TKIP

WPA2 and AES

4
New cards

What are the two methods that a wireless NIC can use to discover an AP? (Choose two.)

transmitting a probe request

sending an ARP request broadcast

receiving a broadcast beacon frame

initiating a three-way handshake

sending a multicast frame

transmitting a probe request

receiving a broadcast beacon frame

5
New cards

What address and prefix length is used when configuring an IPv6 default static route?

::/0

::1/128

0.0.0.0/0

FF02::1/8

::/0

6
New cards

Match the dynamic routing protocol component "Data Structures" to the characteristic

Manually implemented routes by an administrator

A finite list of steps used to determine the best path

Tables or databases that are stored in RAM

Exchanges routing information and maintains accurate information about networks

Tables or databases that are stored in RAM

7
New cards

Match the dynamic routing protocol component "Routing Protocol message" to the characteristic

Manually implemented routes by an administrator

A finite list of steps used to determine the best path

Tables or databases that are stored in RAM

Exchanges routing information and maintains accurate information about networks

Exchanges routing information and maintains accurate information about networks

8
New cards

Match the dynamic routing protocol component "Algorithm" to the characteristic

Manually implemented routes by an administrator

A finite list of steps used to determine the best path

Tables or databases that are stored in RAM

Exchanges routing information and maintains accurate information about networks

A finite list of steps used to determine the best path

9
New cards

Which statement describes the behavior of a switch when the MAC address table is full?

It treats frames as unknown unicast and floods all incoming frames to all ports on the switch.

It treats frames as unknown unicast and floods all incoming frames to all ports across multiple switches.

It treats frames as unknown unicast and floods all incoming frames to all ports within the local VLAN.

It treats frames as unknown unicast and floods all incoming frames to all ports within the collision domain.

It treats frames as unknown unicast and floods all incoming frames to all ports within the local VLAN.

10
New cards

Which term describes the role of a Cisco switch in the 802.1X port-based access control?

agent

supplicant

authenticator

authentication server

authenticator

11
New cards

What is a result of connecting two or more switches together?

The number of broadcast domains is increased.

The size of the broadcast domain is increased.

The number of collision domains is reduced.

The size of the collision domain is increased.

The size of the broadcast domain is increased.

12
New cards

A small publishing company has a network design such that when a broadcast is sent on the LAN, 200 devices receive the transmitted broadcast. How can the network administrator reduce the number of devices that receive broadcast traffic?

Add more switches so that fewer devices are on a particular switch.

Replace the switches with switches that have more ports per switch. This will allow more devices on a particular switch.

Segment the LAN into smaller LANs and route between them.

Replace at least half of the switches with hubs to reduce the size of the broadcast domain.

Segment the LAN into smaller LANs and route between them.

13
New cards

What are two switch characteristics that could help alleviate network congestion? (Choose two.)

fast internal switching

large frame buffers

store-and-forward switching

low port density

frame check sequence (FCS) check

fast internal switching

large frame buffers

14
New cards

A network engineer is configuring a LAN with a redundant first hop to make better use of the available network resources. Which protocol should the engineer implement?

FHRP

GLBP

HSRP

VRRP

GLBP

15
New cards

After sticky learning of MAC addresses is enabled, what action is needed to prevent dynamically learned MAC addresses from being lost in the event that an associated interface goes down?

Reboot the switch.

Copy the running configuration to the startup configuration.

Shut down the interface then enable it again with the no shutdown command.

Configure port security for violation protect mode.

Copy the running configuration to the startup configuration.

16
New cards

A small coffee shop is offering free Wi-Fi to customers. The network includes a wireless router and a DSL modem that is connected to the local phone company. What method is typically used to configure the connection to the phone company?

Set the WAN connection in the wireless router as a DHCP client.

Set the connection between the wireless router and the DSL modem as a private IP network.

Set the DSL modem as a DHCP client to get a public IP address from the wireless router.

Set the DSL modem as a DHCP client to the phone company and a DHCP server for the internal connection.

Set the WAN connection in the wireless router as a DHCP client.

17
New cards

Which three components are combined to form a bridge ID?

MAC address

extended system ID

IP address

cost

bridge priority

port ID

MAC address

extended system ID

bridge priority

18
New cards

What is an advantage of PVST+?

PVST+ requires fewer CPU cycles for all the switches in the network.

PVST+ reduces bandwidth consumption compared to traditional implementations of STP that use CST.

PVST+ optimizes performance on the network through autoselection of the root bridge.

PVST+ optimizes performance on the network through load sharing.

PVST+ optimizes performance on the network through load sharing.

19
New cards

Which problem is evident if the show ip interface command shows that the interface is down and the line protocol is down?

An encapsulation mismatch has occurred.

A cable has not been attached to the port.

The no shutdown command has not been issued on the interface.

There is an IP address conflict with the configured address on the interface.

A cable has not been attached to the port.

20
New cards

A technician is configuring a new Cisco 2960 switch. What is the effect of issuing the BranchSw(config)#interface VLAN88 command?

It updates the MAC address table for the associated port.

It applies an IPv4 address to the virtual interface.

It permits an IPv6 address to be configured on a switch physical interface.

It applies an IPv6 address to the virtual interface.

It enters configuration mode for a switch virtual interface.

It enters configuration mode for a switch virtual interface.

21
New cards

In what situation would a Layer 2 switch have an IP address configured?

when the Layer 2 switch is using a routed port

when the Layer 2 switch needs to be remotely managed

when the Layer 2 switch is the default gateway of user traffic

when the Layer 2 switch needs to forward user traffic to another device

when the Layer 2 switch needs to be remotely managed

22
New cards

Which command would create a valid IPv6 default route?

ipv6 route ::/0 2001:db8:acad:2::a

ipv6 route ::/0 fe80::1

ipv6 route ::/128 2001:db8:acad:1::1

ipv6 route 2001:db8:acad:1::/64 ::1

ipv6 route ::/0 2001:db8:acad:2::a

23
New cards

A junior technician was adding a route to a LAN router. A traceroute to a device on the new network revealed a wrong path and unreachable status. What should be done or checked?

Create a floating static route to that network.

Check the configuration on the floating static route and adjust the AD.

Check the configuration of the exit interface on the new static route.

Verify that the static route to the server is present in the routing table.

Check the configuration of the exit interface on the new static route.

24
New cards

Which command will start the process to bundle two physical interfaces to create an EtherChannel group via LACP?

channel-group 2 mode auto

interface port-channel 2

channel-group 1 mode desirable

interface range GigabitEthernet 0/4 - 5

interface range GigabitEthernet 0/4 - 5

25
New cards

Which type of traffic is designed for a native VLAN?

management

user-generated

tagged

untagged

untagged

26
New cards

Match the DTP mode "Dynamic Auto" with its function

Passively waits for the neighbor to initiate trunking

Requires manual configuration of trunking and nontrunking

Actively attempts to convert the link to a trunk

Permanent trunking mode

Passively waits for the neighbor to initiate trunking

27
New cards

Match the DTP mode "Dynamic desirable" with its function

Passively waits for the neighbor to initiate trunking

Requires manual configuration of trunking and nontrunking

Actively attempts to convert the link to a trunk

Permanent trunking mode

Actively attempts to convert the link to a trunk

28
New cards

Match the DTP mode "Trunk" with its function

Passively waits for the neighbor to initiate trunking

Requires manual configuration of trunking and nontrunking

Actively attempts to convert the link to a trunk

Permanent trunking mode

Permanent trunking mode

29
New cards

Match the DTP mode "Nonegotiate" with its function

Passively waits for the neighbor to initiate trunking

Requires manual configuration of trunking and nontrunking

Actively attempts to convert the link to a trunk

Permanent trunking mode

Requires manual configuration of trunking and nontrunking

30
New cards

What type of VLAN is configured specifically for network traffic such as SSH, Telnet, HTTPS, HTTP, and SNMP?

management VLAN

security VLAN

trunk VLAN

voice VLAN

management VLAN

31
New cards

A network administrator is implementing DHCPv6 for the company. The administrator configures a router to send RA messages with M flag as 1 by using the interface command 'ipv6 nd managed-config-flag' . What effect will this configuration have on the operation of the clients?

Clients must use the information that is contained in RA messages.

Clients must use all configuration information that is provided by a DHCPv6 server.

Clients must use the prefix and prefix length that are provided by a DHCPv6 server and generate a random interface ID.

Clients must use the prefix and prefix length that are provided by RA messages and obtain additional information from a DHCPv6 server.

Clients must use all configuration information that is provided by a DHCPv6 server.

32
New cards

On which port should Dynamic ARP Inspection (DAI) be configured on a switch?

access ports only

any untrusted port

an uplink port to another switch

on any port where DHCP snooping is disabled

an uplink port to another switch

33
New cards

Which Cisco solution helps prevent ARP spoofing and ARP poisoning attacks?

Dynamic ARP Inspection

IP Source Guard

DHCP Snooping

Port Security

Dynamic ARP Inspection

34
New cards

What is the reason for disabling SSID broadcasting and changing the default SSID on a wireless access point?

Wireless clients must then have the SSID manually configured to connect to the wireless network.

Disabling SSID broadcasting frees up radio frequency bandwidth and increases the data throughput of the access point.

Anyone with the default SSID can gain access to the access point and change the configuration.

The access point stops broadcasting its own MAC address, thus preventing unauthorized wireless clients from connecting to the network.

Wireless clients must then have the SSID manually configured to connect to the wireless network.

35
New cards

What are two characteristics of Cisco Express Forwarding (CEF)? (Choose two.)

When a packet arrives on a router interface, it is forwarded to the control plane where the CPU searches for a match in the fast-switching cache.

This is the fastest forwarding mechanism on Cisco routers and multilayer switches.

With this switching method, flow information for a packet is stored in the fast-switching cache to forward future packets to the same destination without CPU intervention.

When a packet arrives on a router interface, it is forwarded to the control plane where the CPU matches the destination address with a matching routing table entry.

Packets are forwarded based on information in the FIB and an adjacency table.

This is the fastest forwarding mechanism on Cisco routers and multilayer switches.

Packets are forwarded based on information in the FIB and an adjacency table.

36
New cards

A network administrator of a college is configuring WLAN security with WPA2 Enterprise authentication. Which server is required when deploying this type of authentication?

AAA

RADIUS

DHCP

SNMP

RADIUS

37
New cards

What is a potential issue when using the WLC to upgrade and deploy the latest firmware image to all APs?

Usernames and passwords must be manually entered into the AP so that WLAN authentication continues during the upgrade.

Only one of the two bands would work at a time.

Users will not be able to use the WLAN.

Old 802.11 standards may not be supported anymore.

Users will not be able to use the WLAN.

38
New cards

A network administrator is configuring a WLC to provide WLAN access to users in an office building. When testing the newly created WLAN, the administrator does not see the SSID from a wireless device. What is a possible cause?

The WLAN security setting is incorrect.

The APs have not been configured for the new WLAN.

The new WLAN needs to be enabled.

The RADUIS server is not operational.

The new WLAN needs to be enabled.

39
New cards

What is the best way to prevent a VLAN hopping attack?

Disable trunk negotiation for trunk ports and statically set nontrunk ports as access ports.

Disable STP on all nontrunk ports.

Use VLAN 1 as the native VLAN on trunk ports.

Use ISL encapsulation on all trunk links.

Disable trunk negotiation for trunk ports and statically set nontrunk ports as access ports.

40
New cards

An administrator has configured a DHCPv4 relay router and issued these commands:

Router(config)# interface g0/0

Router(config-if)# ip address 10.0.1.1 255.255.255.0

Router(config-if)# no shutdown

Router(config-if)# exit

Router(config)# ip dhcp pool RELAY

Router(dhcp-config)# end

The clients are not receiving IP parameters from the DHCPv4 server. What is a possible cause?

The IP address is incorrect for the subnet mask that is used.

The pool cannot be named 'RELAY'.

The ip helper-address command is missing.

The router is configured as a DHCPv4 client.

The ip helper-address command is missing.

41
New cards

Consider the following command:

ip route 192.168.10.0 255.255.255.0 10.10.10.2 5

What does the 5 at the end of the command signify?

exit interface

maximum number of hops to the 192.168.10.0/24 network

metric

administrative distance

administrative distance

42
New cards

Which option shows a correctly configured IPv4 default static route?

ip route 0.0.0.0 255.255.255.0 S0/0/0

ip route 0.0.0.0 0.0.0.0 S0/0/0

ip route 0.0.0.0 255.255.255.255 S0/0/0

ip route 0.0.0.0 255.0.0.0 S0/0/0

ip route 0.0.0.0 0.0.0.0 S0/0/0

43
New cards

What is a method to launch a VLAN hopping attack?

introducing a rogue switch and enabling trunking

sending spoofed native VLAN information

sending spoofed IP addresses from the attacking host

flooding the switch with MAC addresses

introducing a rogue switch and enabling trunking

44
New cards

A cybersecurity analyst is using the macof tool to evaluate configurations of switches deployed in the backbone network of an organization. Which type of LAN attack is the analyst targeting during this evaluation?

VLAN hopping

DHCP spoofing

MAC address table overflow

VLAN double-tagging

MAC address table overflow

45
New cards

Match the forwarding characteristic to the type "Cut-through"

Appropriate for high performance applications

Error checking before forwarding

Forwarding process can begin after receiving the destination address

Forwarding process only begins after receiving the entire frame

May forward invalid frames

Only forwards valid frames

Appropriate for high performance applications

Forwarding process can begin after receiving the destination address

May forward invalid frames

46
New cards

Match the forwarding characteristic to the type "Store-and-Forward"

Appropriate for high performance applications

Error checking before forwarding

Forwarding process can begin after receiving the destination address

Forwarding process only begins after receiving the entire frame

May forward invalid frames

Only forwards valid frames

Error checking before forwarding

Forwarding process only begins after receiving the entire frame

Only forwards valid frames

47
New cards

Which statement is correct about how a Layer 2 switch determines how to forward frames?

Frame forwarding decisions are based on MAC address and port mappings in the CAM table.

Only frames with a broadcast destination address are forwarded out all active switch ports.

Unicast frames are always forwarded regardless of the destination MAC address.

Cut-through frame forwarding ensures that invalid frames are always dropped.

Frame forwarding decisions are based on MAC address and port mappings in the CAM table.

48
New cards

Which statement describes a result after multiple Cisco LAN switches are interconnected?

The broadcast domain expands to all switches.

One collision domain exists per switch.

There is one broadcast domain and one collision domain per switch.

Frame collisions increase on the segments connecting the switches.

Unicast frames are always forwarded regardless of the destination MAC address.

The broadcast domain expands to all switches.

49
New cards

Match the link state to the interface and protocol status "administratively down"

Disabled

Layer 1 problem

Layer 2 problem

Operational

Disabled

50
New cards

Match the link state to the interface and protocol status "up/up"

Disabled

Layer 1 problem

Layer 2 problem

Operational

Operational

51
New cards

Match the link state to the interface and protocol status "down/down"

Disabled

Layer 1 problem

Layer 2 problem

Operational

Layer 1 problem

52
New cards

Match the link state to the interface and protocol status "up/down"

Disabled

Layer 1 problem

Layer 2 problem

Operational

Layer 2 problem

53
New cards

An administrator is trying to remove configurations from a switch. After using the command erase startup-config and reloading the switch, the administrator finds that VLANs 10 and 100 still exist on the switch. Why were these VLANs not removed?

Because these VLANs are stored in a file that is called vlan.dat that is located in flash memory, this file must be manually deleted.

These VLANs cannot be deleted unless the switch is in VTP client mode.

These VLANs are default VLANs that cannot be removed.

These VLANs can only be removed from the switch by using the no vlan 10 and no vlan 100 commands.

Because these VLANs are stored in a file that is called vlan.dat that is located in flash memory, this file must be manually deleted.

54
New cards

Match the description to the following VLAN type "Default VLAN"

Configured to carry user generated traffic

All switch ports are assigned to this VLAN after initial bootup of the switch

Carries untagged traffic

An IP address and subnet mask are assigned to this VLAN, allowing the switch to be accessed by HTTP, Telnet, SSH or SNMP

All switch ports are assigned to this VLAN after initial bootup of the switch

55
New cards

Match the description to the following VLAN type "management VLAN"

Configured to carry user generated traffic

All switch ports are assigned to this VLAN after initial bootup of the switch

Carries untagged traffic

An IP address and subnet mask are assigned to this VLAN, allowing the switch to be accessed by HTTP, Telnet, SSH or SNMP

An IP address and subnet mask are assigned to this VLAN, allowing the switch to be accessed by HTTP, Telnet, SSH or SNMP

56
New cards

Match the description to the following VLAN type "data VLAN"

Configured to carry user generated traffic

All switch ports are assigned to this VLAN after initial bootup of the switch

Carries untagged traffic

An IP address and subnet mask are assigned to this VLAN, allowing the switch to be accessed by HTTP, Telnet, SSH or SNMP

Configured to carry user generated traffic

57
New cards

Match the description to the following VLAN type "native VLAN"

Configured to carry user generated traffic

All switch ports are assigned to this VLAN after initial bootup of the switch

Carries untagged traffic

An IP address and subnet mask are assigned to this VLAN, allowing the switch to be accessed by HTTP, Telnet, SSH or SNMP

Carries untagged traffic

58
New cards

What is a secure configuration option for remote access to a network device?

Configure an ACL and apply it to the VTY lines.

Configure 802.1x.

Configure SSH.

Configure Telnet.

Configure SSH.

59
New cards

Which wireless encryption method is the most secure?

WPA2 with AES

WPA2 with TKIP

WEP

WPA

WPA2 with AES

60
New cards

After attaching four PCs to the switch ports, configuring the SSID and setting authentication properties for a small office network, a technician successfully tests the connectivity of all PCs that are connected to the switch and WLAN. A firewall is then configured on the device prior to connecting it to the Internet. What type of network device includes all of the described features?

firewall appliance

wireless router

switch

standalone wireless access point

wireless router

61
New cards

What protocol or technology disables redundant paths to eliminate Layer 2 loops?

VTP

STP

EtherChannel

DTP

STP

62
New cards

Which two VTP modes allow for the creation, modification, and deletion of VLANs on the local switch? (Choose two.)

client

master

distribution

slave

server

transparent

server

transparent

63
New cards

Which three steps should be taken before moving a Cisco switch to a new VTP management domain? (Choose three.)

Configure the switch with the name of the new management domain.

Reset the VTP counters to allow the switch to synchronize with the other switches in the domain.

Configure the VTP server in the domain to recognize the BID of the new switch.

Download the VTP database from the VTP server in the new domain.

Select the correct VTP mode and version.

Reboot the switch.

Configure the switch with the name of the new management domain.

Select the correct VTP mode and version.

Reboot the switch.

64
New cards

A network administrator is preparing the implementation of Rapid PVST+ on a production network. How are the Rapid PVST+ link types determined on the switch interfaces?

Link types can only be configured on access ports configured with a single VLAN.

Link types can only be determined if PortFast has been configured.

Link types are determined automatically.

Link types must be configured with specific port configuration commands.

Link types are determined automatically.

65
New cards

How will a router handle static routing differently if Cisco Express Forwarding is disabled?

It will not perform recursive lookups.

Ethernet multiaccess interfaces will require fully specified static routes to avoid routing inconsistencies.

Static routes that use an exit interface will be unnecessary.

Serial point-to-point interfaces will require fully specified static routes to avoid routing inconsistencies.

Ethernet multiaccess interfaces will require fully specified static routes to avoid routing inconsistencies.

66
New cards

Compared with dynamic routes, what are two advantages of using static routes on a router? (Choose two.)

They improve network security.

They take less time to converge when the network topology changes.

They improve the efficiency of discovering neighboring networks.

They use fewer router resources.

They improve network security.

They use fewer router resources.

67
New cards

What is the effect of entering the spanning-tree portfast configuration command on a switch?

It disables an unused port.

It disables all trunk ports.

It enables portfast on a specific switch interface.

It checks the source L2 address in the Ethernet header against the sender L2 address in the ARP body.

It enables portfast on a specific switch interface.

68
New cards

What is the IPv6 prefix that is used for link-local addresses?

FF01::/8

2001::/3

FC00::/7

FE80::/10

FE80::/10

69
New cards

Which two statements are characteristics of routed ports on a multilayer switch? (Choose two.)

In a switched network, they are mostly configured between switches at the core and distribution layers.

The interface vlan command has to be entered to create a VLAN on routed ports.

They support subinterfaces, like interfaces on the Cisco IOS routers.

They are used for point-to-multipoint links.

They are not associated with a particular VLAN.

They are not associated with a particular VLAN.

70
New cards

Successful inter-VLAN routing has been operating on a network with multiple VLANs across multiple switches for some time. When an inter-switch trunk link fails and Spanning Tree Protocol brings up a backup trunk link, it is reported that hosts on two VLANs can access some, but not all the network resources that could be accessed previously. Hosts on all other VLANS do not have this problem. What is the most likely cause of this problem?

The protected edge port function on the backup trunk interfaces has been disabled.

The allowed VLANs on the backup link were not configured correctly.

Dynamic Trunking Protocol on the link has failed.

Inter-VLAN routing also failed when the trunk link failed.

The protected edge port function on the backup trunk interfaces has been disabled.

71
New cards

Which command will start the process to bundle two physical interfaces to create an EtherChannel group via LACP?

interface port-channel 2

channel-group 1 mode desirable

interface range GigabitEthernet 0/4 - 5

channel-group 2 mode auto

interface range GigabitEthernet 0/4 - 5

72
New cards

What action takes place when a frame entering a switch has a multicast destination MAC address?

The switch will forward the frame out all ports except the incoming port.

The switch forwards the frame out of the specified port.

The switch adds a MAC address table entry mapping for the destination MAC address and the ingress port.

The switch replaces the old entry and uses the more current port.

The switch will forward the frame out all ports except the incoming port.

73
New cards

A junior technician was adding a route to a LAN router. A traceroute to a device on the new network revealed a wrong path and unreachable status. What should be done or checked?

Verify that there is not a default route in any of the edge router routing tables.

Check the configuration on the floating static route and adjust the AD.

Create a floating static route to that network.

Check the configuration of the exit interface on the new static route.

Check the configuration of the exit interface on the new static route.

74
New cards

Select the three PAgP channel establishment modes. (Choose three.)

auto

default

passive

desirable

extended

on

auto

desirable

on

75
New cards

A static route has been configured on a router. However, the destination network no longer exists. What should an administrator do to remove the static route from the routing table?

Remove the route using the no ip route command.

Change the administrative distance for that route.

Change the routing metric for that route.

Nothing. The static route will go away on its own.

Remove the route using the no ip route command.

76
New cards

45. What two default wireless router settings can affect network security? (Choose two.)

The SSID is broadcast.

MAC address filtering is enabled.

WEP encryption is enabled.

The wireless channel is automatically selected.

A well-known administrator password is set.

The SSID is broadcast.

A well-known administrator password is set.

77
New cards

What is the common term given to SNMP log messages that are generated by network devices and sent to the SNMP server?

traps

acknowledgments

auditing

warnings

traps

78
New cards

A network administrator is adding a new WLAN on a Cisco 3500 series WLC. Which tab should the administrator use to create a new VLAN interface to be used for the new WLAN?

WIRELESS

MANAGEMENT

CONTROLLER

WLANs

CONTROLLER

79
New cards

A network administrator is configuring a WLAN. Why would the administrator change the default DHCP IPv4 addresses on an AP?

to restrict access to the WLAN by authorized, authenticated users only

to monitor the operation of the wireless network

to reduce outsiders intercepting data or accessing the wireless network by using a well-known address range

to reduce the risk of interference by external devices such as microwave ovens

to reduce outsiders intercepting data or accessing the wireless network by using a well-known address range

80
New cards

Which two functions are performed by a WLC when using split media access control (MAC)? (Choose two.)

packet acknowledgments and retransmissions

frame queuing and packet prioritization

beacons and probe responses

frame translation to other protocols

association and re-association of roaming clients

frame translation to other protocols

association and re-association of roaming clients

81
New cards

On what switch ports should BPDU guard be enabled to enhance STP stability?

all PortFast-enabled ports

only ports that are elected as designated ports

only ports that attach to a neighboring switch

all trunk ports that are not root ports

all PortFast-enabled ports

82
New cards

Which network attack is mitigated by enabling BPDU guard?

Rogue switches on a network

CAM table overflow attacks

MAC address spoofing

rogue DHCP servers on a network

rogue switches on a network

83
New cards

Why is DHCP snooping required when using the Dynamic ARP Inspection feature?

It relies on the settings of trusted and untrusted ports set by DHCP snooping.

It uses the MAC address table to verify the default gateway IP address.

It redirects ARP requests to the DHCP server for verification.

It uses the MAC-address-to-IP-address binding database to validate an ARP packet.

It uses the MAC-address-to-IP-address binding database to validate an ARP packet.

84
New cards

A network administrator is configuring a new Cisco switch for remote management access. Which three items must be configured on the switch for the task? (Choose three.)

IP address

VTP domain

vty lines

default VLAN

default gateway

loopback address

IP address

vty lines

default gateway

85
New cards

A technician is troubleshooting a slow WLAN and decides to use the split-the-traffic approach. Which two parameters would have to be configured to do this? (Choose two.)

Configure the 5 GHz band for streaming multimedia and time sensitive traffic.

Configure the security mode to WPA Personal TKIP/AES for one network and WPA2 Personal AES for the other network

Configure the 2.4 GHz band for basic internet traffic that is not time sensitive.

Configure the security mode to WPA Personal TKIP/AES for both networks.

Configure a common SSID for both split networks.

Configure the 5 GHz band for streaming multimedia and time sensitive traffic.

Configure the 2.4 GHz band for basic internet traffic that is not time sensitive.

86
New cards

A company has just switched to a new ISP. The ISP has completed and checked the connection from its site to the company. However, employees at the company are not able to access the internet. What should be done or checked?

Verify that the static route to the server is present in the routing table.

Check the configuration on the floating static route and adjust the AD.

Ensure that the old default route has been removed from the company edge routers.

Create a floating static route to that network.

Ensure that the old default route has been removed from the company edge routers.

87
New cards

Which information does a switch use to populate the MAC address table?

the destination MAC address and the incoming port

the destination MAC address and the outgoing port

the source and destination MAC addresses and the incoming port

the source and destination MAC addresses and the outgoing port

the source MAC address and the incoming port

the source MAC address and the outgoing port

the source MAC address and the incoming port

88
New cards

Which type of static route is configured with a greater administrative distance to provide a backup route to a route learned from a dynamic routing protocol?

floating static route

default static route

summary static route

standard static route

floating static route

89
New cards

What action takes place when a frame entering a switch has a unicast destination MAC address appearing in the MAC address table?

The switch updates the refresh timer for the entry.

The switch forwards the frame out of the specified port.

The switch purges the entire MAC address table.

The switch replaces the old entry and uses the more current port.

The switch forwards the frame out of the specified port.

90
New cards

What protocol or technology allows data to transmit over redundant switch links?

EtherChannel

DTP

STP

VTP

EtherChannel

91
New cards

What is the effect of entering the shutdown configuration command on a switch?

It enables BPDU guard on a specific port.

It disables an unused port.

It enables portfast on a specific switch interface.

It disables DTP on a non-trunking interface.

It disables an unused port.

92
New cards

What would be the primary reason an attacker would launch a MAC address overflow attack?

so that the switch stops forwarding traffic

so that legitimate hosts cannot obtain a MAC address

so that the attacker can see frames that are destined for other hosts

so that the attacker can execute arbitrary code on the switch

so that the attacker can see frames that are destined for other hosts

93
New cards

During the AAA process, when will authorization be implemented?

Immediately after successful authentication against an AAA data source

Immediately after AAA accounting and auditing receives detailed reports

Immediately after an AAA client sends authentication information to a centralized server

Immediately after the determination of which resources a user can access

Immediately after successful authentication against an AAA data source

94
New cards

A company security policy requires that all MAC addressing be dynamically learned and added to both the MAC address table and the running configuration on each switch. Which port security configuration will accomplish this?

auto secure MAC addresses

dynamic secure MAC addresses

static secure MAC addresses

sticky secure MAC addresses

sticky secure MAC addresses

95
New cards

Which three Wi-Fi standards operate in the 2.4GHz range of frequencies? (Choose three.)

802.11a

802.11b

802.11g

802.11n

802.11ac

802.11b

802.11g

802.11n

96
New cards

To obtain an overview of the spanning tree status of a switched network, a network engineer issues the show spanning-tree command on a switch. Which two items of information will this command display? (Choose two.)

The root bridge BID.

The role of the ports in all VLANs.

The status of native VLAN ports.

The number of broadcasts received on each root port.

The IP address of the management VLAN interface.

The root bridge BID.

The role of the ports in all VLANs.

97
New cards

Which method of IPv6 prefix assignment relies on the prefix contained in RA messages?

EUI-64

SLAAC

static

stateful DHCPv6

SLAAC

98
New cards

Which two protocols are used to provide server-based AAA authentication? (Choose two.)

802.1x

SSH

SNMP

TACACS+

RADIUS

TACACS+

RADIUS

99
New cards

A network administrator is configuring a WLAN. Why would the administrator disable the broadcast feature for the SSID?

to eliminate outsiders scanning for available SSIDs in the area

to reduce the risk of interference by external devices such as microwave ovens

to reduce the risk of unauthorized APs being added to the network

to provide privacy and integrity to wireless traffic by using encryption

to eliminate outsiders scanning for available SSIDs in the area

100
New cards

Which mitigation technique would prevent rogue servers from providing false IP configuration parameters to clients?

implementing port security

turning on DHCP snooping

disabling CDP on edge ports

implementing port-security on edge ports

turning on DHCP snooping

Explore top notes

note
Criminal Psychology
Updated 682d ago
0.0(0)
note
COM 100 Test: Chapters 1-8
Updated 542d ago
0.0(0)
note
6.5: The Great Depression
Updated 1253d ago
0.0(0)
note
CGO casus 2
Updated 437d ago
0.0(0)
note
Beck Anxiety Inventory
Updated 1163d ago
0.0(0)
note
Ch. 3; Energy
Updated 1029d ago
0.0(0)
note
Criminal Psychology
Updated 682d ago
0.0(0)
note
COM 100 Test: Chapters 1-8
Updated 542d ago
0.0(0)
note
6.5: The Great Depression
Updated 1253d ago
0.0(0)
note
CGO casus 2
Updated 437d ago
0.0(0)
note
Beck Anxiety Inventory
Updated 1163d ago
0.0(0)
note
Ch. 3; Energy
Updated 1029d ago
0.0(0)

Explore top flashcards

flashcards
Week 9
31
Updated 539d ago
0.0(0)
flashcards
Module 11
65
Updated 732d ago
0.0(0)
flashcards
troika “my family”
21
Updated 1219d ago
0.0(0)
flashcards
AP Spanish Literature - Autores
39
Updated 330d ago
0.0(0)
flashcards
Learn to Lead Chapter 1 Review
28
Updated 769d ago
0.0(0)
flashcards
Week 9
31
Updated 539d ago
0.0(0)
flashcards
Module 11
65
Updated 732d ago
0.0(0)
flashcards
troika “my family”
21
Updated 1219d ago
0.0(0)
flashcards
AP Spanish Literature - Autores
39
Updated 330d ago
0.0(0)
flashcards
Learn to Lead Chapter 1 Review
28
Updated 769d ago
0.0(0)